Computer Science ›› 2026, Vol. 53 ›› Issue (8): 455-468.doi: 10.11896/jsjkx.251000056

• Computer Software • Previous Articles     Next Articles

Multi-aggregation Heterogeneous Graph Neural Network-based Saturation Attack DetectionMethod for SDN

QIAN Qing1,2, RAN Longwen1, WANG Huan1,2, CUI Yunhe3, WANG Lingyun1   

  1. 1 School of Information, Guizhou University of Finance and Economics, Guiyang 550025, China
    2 Guizhou Province Key Laboratory of Computing and Network Convergence, Guiyang 550025, China
    3 Engineering Research Center of Text Computing and Cognitive Intelligence, Ministry of Education, School of Computer Science and Technology, Guizhou University, Guiyang 550025, China
  • Received:2025-10-14 Revised:2025-11-22 Published:2026-08-17
  • About author:QIAN Qing,born in 1986,Ph.D,asso-ciate professor,is a member of CCF(No.K8203S).Her main research interests include natural language processing,digital media forensics and multimedia signal processing.
    CUl Yunhe,born in 1987,Ph.D,asso-ciate professor,is a member of CCF(No.F3600M).His main research interests include lightweight large mo-dels,network security,software-defined networks,data center networks and network telemetry.
  • Supported by:
    National Natural Science Foundation of China(62462010, 61902085),Construction Project for Guizhou Provincial Key Laboratory(QKHPTZSYS[2025] 005),Guizhou Provincial Basic Research Program General Projects(QKH-Basic-MS(2026)056) and Natural Science Researching Program of D.o.E. of Guizhou(Qian Edu.& Tech. [2023] 065,Qian Edu. & Tech. [2023] 014).

Abstract: Saturation attack is a resource-consuming attack and one of the key cybersecurity threats facing software-defined networks.The current saturation attack detection methods based on graph neural networks mainly model network flows as isomorphic structures and achieve certain results,However,they fail to fully capture the complex interaction characteristics between network devices and traffic during the detection process.At the same time,the existing methods have limitations in the node information aggregation mechanism,which limits the further improvement of their detection accuracy.To solve the above problems,this paper proposes a saturation attack detection method based on a heterogeneous hierarchical graph neural network,MARATHON.This method constructs a heterogeneous flow graph structure that can accurately characterize the relationship between traffic,host and switch,which fully considers the differentiated characteristics of traffic,host and switch,so as to effectively describe the interaction behavior between devices and traffic.On this basis,a new graph neural network detection model is designed,which integrates three types of aggregation mechanisms:host/switch isomorphic aggregation,host-traffic/switch-traffic heterogeneous aggregation,and traffic-host-traffic/traffic-switch-traffic metapath aggregation,which fully mines the potential discriminant information in the network flow through hierarchical feature extraction strategy to improve the accuracy of attack detection.Experimental results on the public datasets IMC10 and 4SICS show that the MARATHON method is better than the existing mainstream methods in terms of accuracy,recall and F1 score.Specifically,under the Fattree topology of IMC10 dataset,the accuracy and macro recall of MARATHON reach 97.5% and 98.3%,respectively.Under the Agis topology of the 4SICS dataset,the accuracy and macro recall are further improved to 98.4% and 98.5%,which verifies the effectiveness and superiority of the proposed method.

Key words: Saturation attack detection, Software-defined network, Heterogeneous graph convolution

CLC Number: 

  • TP393
[1] YE M,WANG J,JIANG Q,et al.SDN-based Integrated Communication and Storage Edge In-network Storage Node Selection Method[J].Computer Science,2025,52(8):343-353.
[2] WU Z H,WEI Q,WANG Q X.Survey for Attack and Defense Approaches of OpenFlow-enabled Software Defined Network[J].Computer Science,2017,44(6):121-132.
[3] CUI Y,QIAN Q,GUO C,et al.Towards DDoS detection mecha-nisms in software-defined networking[J].Journal of Network and Computer Applications,2021,190:103156.
[4] TANG D,GAO C,LIANG W,et al.FTMaster:A detection and mitigation system of low-rate flow table overflow attacks via SDN[J].IEEE Transactions on Network and Service Management,2023,20(4):5073-5084.
[5] TANG D,ZHENG Z,YIN C,et al.FTODefender:An efficient flow table overflow attacksdefending system in SDN[J].Expert Systems with Applications,2024,237:121460.
[6] ZHENG J,LI D.GCN-TC:Combining trace graph with statistical features for network traffic classification[C]//ICC 2019-2019 IEEE International Conference on Communications(ICC).IEEE,2019:1-6.
[7] DENG X,ZHU J,PEI X,et al.Flow topology-based graph con-volutional network for intrusion detection in label-limited IoT networks[J].IEEE Transactions on Network and Service Ma-nagement,2022,20(1):684-696.
[8] WANG K,CUI Y,QIAN Q,et al.USAGE:Uncertain flowgraph and spatio-temporal graph convolutional network-based saturation attack detection method[J].Journal of Network and Computer Applications,2023,219:103722.
[9] RAN L,CUI Y,ZHAO J,et al.TITAN:Combining a bidirectional forwarding graph and GCN to detect saturation attack targeted at SDN[J].PLoS One,2024,19(4):e0299846.
[10] RAN L,CUI Y,SHEN G,et al.Towards Saturation Attack De-tection in SDN:A Device Hyperedge Graph and Flow-Device Hypergraph Neural Network-Based Method[C]//International Conference on Intelligent Computing.Singapore:Springer Nature Singapore,2025:50-62.
[11] JI Z,CUI Y,GUO Y,et al.Towards saturation attack detection in SDN:a multi-edge representation learning-based method[J].Journal of King Saud University Computer and Information Sciences,2025,37(6):138.
[12] KUBRA K,LEVENT A,GURKAN G,et al.JESS:Joint Entropy-Based DDoS Defense Scheme in SDN[J].IEEE Journal on Selected Areas in Communications,2018,36(10):2358-2372.
[13] LI Z,XING W,KHAMAISEH S,et al.Detecting saturation attacks based on self-similarity of OpenFlow traffic[J].IEEE Transactions on Network and Service Management,2019,17(1):607-621.
[14] NAJAR A A,NAIK S M.Cyber-secure SDN:A CNN-based approach for efficient detection andmitigation of DDoS attacks[J].Computers & Security,2024,139:103716.
[15] HNAMTE V,NAJAR A A,NHUNG-NGUYEN H,et al.DDoSattack detection and mitigation using deep neural network in SDN environment[J].Computers & Security,2024,138:103661.
[16] XU J,WANG L,XU Z.An enhanced saturation attack and its mitigation mechanism in software-defined networking[J].Computer Networks,2020,169:107092.
[17] YANG L,SONG Y,GAO S,et al.Griffin:Real-time network intrusion detection system via ensemble of autoencoder in SDN[J].IEEE Transactions on Network and Service Management,2022,19(3):2269-2281.
[18] NAGARAJ K,STARKE A,MCNAIR J.Glass:a graph learning approach for software defined network based smart grid ddos security[C]//ICC 2021-IEEE International Conference on Communications.2021.
[19] CAO Y,JIANG H,DENG Y,et al.Detecting and mitigatingDDoS attacks in SDN using spatial-temporal graph convolutio-nal network[J].IEEE Transactions on Dependable and Secure Computing,2021,19(6):3855-3872.
[20] DU R,HUANG M,LIU F.Multiple Classification Algorithm Based on Graph Convolutional Neural Network for Intrusion Detection[J].Signal,Image and Video Processing,2025,19(6):1-8.
[21] YE Y,HOU S,CHEN L,et al.Out-of-sample node representation learning for heterogeneous graph in real-time android malware detection[C]//28th International Joint Conference on Artificial Intelligence(IJCAI).2019.
[22] SUN X,YANG J,WANG Z,et al.Hgdom:Heterogeneousgraph convolutional networks for malicious domain detection[C]//NOMS 2020-2020 IEEE/IFIP Network Operations and Management Symposium.IEEE,2020:1-9.
[23] ZHANG T,XU R,ZHANG J,et al.DSHGT:Dual-Supervisors Heterogeneous GraphTransformer—A Pioneer Study of Using Heterogeneous Graph Learning for Detecting Software Vulnerabilities[J].ACM Transactions on Software Engineering and Methodology,2024,33(8):1-31.
[24] CHEN T,DONG C,LYU M,et al.Apt-kgl:An intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning[J].IEEE Transactions on Dependable and Secure Computing,2022,19(1):1-15.
[25] MUDGAL A,VERMA A,SINGH M,et al.FloRa:Flow table low-rate overflow reconnaissance and detection in SDN[J].IEEE Transactions on Network and Service Management,2024,21(6):6670-6683.
[26] HAMILTON W,YING Z,LESKOVEC J.Inductive representa-tion learning on large graphs[C]//Advances in Neural Information Processing Systems.2017.
[27] SCHLICHTKRULL M,KIPF T N,BLOEM P,et al.Modeling relational data with graph convolutional networks[C]//Euro-pean Semantic Web Conference.Cham:Springer,2018:593-607.
[28] WANG X,JI H,SHI C,et al.Heterogeneous graph attention network[C]//The World Wide Web Conference.2019:2022-2032.
[29] KIPF T N.Semi-supervised classification with graph convolu-tional networks[J].arXiv:1609.02907,2016.
[30] VELIČKOVIĆ P,CUCURULL G,CASANOVA A,et al.Graph attention networks[J].arXiv:1710.10903,2017.
[1] WU Zongming, CAO Jijun, TANG Qiang. Online Parallel SDN Routing Optimization Algorithm Based on Deep Reinforcement Learning [J]. Computer Science, 2025, 52(6A): 240900018-9.
[2] WANG Panxiang, CUI Yunhe, SHEN Guowei, GUO Chun, CHEN Yi, QIAN Qing. EvoTrace:A Lightweight In-band Network Telemetry Method Based on Nonlinear Embedding and Batch Processing [J]. Computer Science, 2025, 52(5): 291-298.
[3] WANG Yijie, GAO Guoju, SUN Yu'e, HUANG He. Flow Cardinality Estimation Method Based on Distributed Sketch in SDN [J]. Computer Science, 2025, 52(2): 268-278.
[4] LIU Haohan, CHEN Zemao. Study on Malicious Access Detection in Industrial Control Networks Based on Dynamic BayesianGames [J]. Computer Science, 2025, 52(1): 383-392.
[5] GU Zhouchao, CHENG Guang, ZHAO Yuyu. Segmental Routing in Band Telemetry Method for Endogenous Secure Switches [J]. Computer Science, 2024, 51(5): 284-292.
[6] LI Chunjiang, YIN Shaoping, CHI Haotian, YANG Jing, GENG Haijun. DDoS Attack Detection Model Based on Statistics and Ensemble Autoencoders in SDN [J]. Computer Science, 2024, 51(11): 389-399.
[7] GENG Haijun, WANG Wei, ZHANG Han, WANG Ling. Routing Protection Scheme with High Failure Protection Ratio Based on Software-defined Network [J]. Computer Science, 2023, 50(9): 337-346.
[8] CHEN Ziqiang, XIA Zhengyou. Failure Recovery Model for Single Link with Congestion-Avoidance in SDN [J]. Computer Science, 2023, 50(4): 212-219.
[9] CHEN Gang, MENG Xiang-ru, KANG Qiao-yan, ZHAI Dong. vSDN Fault Recovery Algorithm Based on Minimum Spanning Tree [J]. Computer Science, 2022, 49(11A): 211200034-7.
[10] ZHOU Jian-xin, ZHANG Zhi-peng, ZHOU Ning. Load Balancing Technology of Segment Routing Based on CKSP [J]. Computer Science, 2020, 47(4): 256-261.
[11] ZHAO Jin-long, ZHANG Guo-min, XING Chang-you, SONG Li-hua, ZONG Yi-ben. Self-adaptive Deception Defense Mechanism Against Network Reconnaissance [J]. Computer Science, 2020, 47(12): 304-310.
[12] ZHANG Zhao, LI Hai-long, HU Lei, DONG Si-qi. Service Function Load Balancing Based on SDN-SFC [J]. Computer Science, 2019, 46(9): 130-136.
[13] ZHANG Fang, DENG Chang-lin, WANG Zhi and GUO Wei. Link Failure Detection and Fast Recovery in Software-defined Satellite Network [J]. Computer Science, 2017, 44(6): 63-67.
[14] LIU Lin and ZHOU Jian-tao. Review for Research of Control Plane in Software-defined Network [J]. Computer Science, 2017, 44(2): 75-81.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!